PT-2024-5979 · Mitel · Mitel 6800 Series+2
Kyle Burns
·
Published
2024-07-17
·
Updated
2025-05-04
·
CVE-2024-41710
CVSS v2.0
7.7
High
| Vector | AV:A/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, versions through R6.4.0.HF1 (R6.4.0.136)
Description
A vulnerability in the Mitel SIP phones could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system. The vulnerability is being exploited by the Aquabot botnet, a Mirai-based malware, to launch DDoS attacks. The botnet is targeting Mitel SIP phones, including the 6800, 6900, and 6900w series, as well as the 6970 Conference Unit.
Recommendations
Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, versions through R6.4.0.HF1 (R6.4.0.136): Update to a newer version that contains a fix for this issue, as the current version is vulnerable to argument injection attacks.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mitel 6800 Series
Mitel 6900 Series
Mitel 6970 Conference Unit